Mattermost Server vulnerabilities
445 known vulnerabilities affecting mattermost/mattermost_server.
Total CVEs
445
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH80MEDIUM308LOW41
Vulnerabilities
Page 19 of 23
CVE-2025-49810P4MEDIUMCVSS 4.3≥ 10.5.0, < 10.5.92025-08-21
CVE-2025-49810 [MEDIUM] CWE-863 CVE-2025-49810: Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows
Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts
nvd
CVE-2026-21386P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.11≥ 11.2.0, < 11.2.3+1 more2026-03-16
CVE-2026-21386 [MEDIUM] CWE-203 CVE-2026-21386: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent e
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent versus private channels. Mattermost Advisory ID:
nvd
CVE-2026-6339P4MEDIUMCVSS 4.3≥ 11.4.0, < 11.4.4≥ 11.5.0, < 11.5.22026-05-18
CVE-2026-6339 [MEDIUM] CWE-346 CVE-2026-6339: Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header
Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member to force the reveal of a burn-on-read message without recipient consent via a crafted Markdown image tag.. Mattermost Advisory ID: MMSA-2026-00636
nvd
CVE-2025-62190P4MEDIUMCVSS 4.3≥ 10.11.0, < 10.11.7≥ 10.12.0, < 10.12.3+1 more2025-12-17
CVE-2025-62190 [MEDIUM] CWE-352 CVE-2025-62190: Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls ve
Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject messages into channels or direct messages via a malicious webpage or crafted link
nvd
CVE-2017-18889P4MEDIUMCVSS 4.3fixed in 4.1.2≥ 4.2.0, < 4.2.1+1 more2020-06-19
CVE-2017-18889 [MEDIUM] CWE-20 CVE-2017-18889: An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could creat
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-message posts via webhooks and slash commands, in the v3 or v4 REST API.
nvd
CVE-2019-20887P4MEDIUMCVSS 4.3fixed in 4.10.6≥ 5.5.0, < 5.5.3+2 more2020-06-19
CVE-2019-20887 [MEDIUM] CWE-862 CVE-2019-20887: An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not hon
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.
nvd
CVE-2018-21252P4MEDIUMCVSS 4.3fixed in 4.10.3≥ 5.0.0, < 5.0.3+2 more2020-06-19
CVE-2018-21252 [MEDIUM] CWE-732 CVE-2018-21252: An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could u
An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail addresses to bypass a domain-based policy for signups.
nvd
CVE-2017-18870P4MEDIUMCVSS 4.3fixed in 4.3.4≥ 4.4.0, < 4.4.5+1 more2020-06-19
CVE-2017-18870 [MEDIUM] CWE-732 CVE-2017-18870: An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook a
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case.
nvd
CVE-2018-21253P4MEDIUMCVSS 4.3fixed in 4.10.2≥ 5.0.0, < 5.0.2+1 more2020-06-19
CVE-2018-21253 [MEDIUM] CWE-732 CVE-2018-21253: An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use th
An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slash command to invite a non-permitted user.
nvd
CVE-2024-4182P4MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.12≥ 9.4.0, < 9.4.5+2 more2024-04-26
CVE-2024-4182 [MEDIUM] CWE-754 CVE-2024-4182: Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to h
Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
nvd
CVE-2024-1952P4MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.92024-02-29
CVE-2024-1952 [MEDIUM] CWE-200 CVE-2024-1952: Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugi
Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member of.
nvd
CVE-2024-1942P4MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.9≥ 9.2.0, < 9.2.5+1 more2024-02-29
CVE-2024-1942 [MEDIUM] CWE-284 CVE-2024-1942: Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata
Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated attacker to access the contents of individual posts in channels they are not a member of.
nvd
CVE-2023-47858P4MEDIUMCVSS 4.3fixed in 8.1.7≥ 9.0.0, < 9.0.5+2 more2024-01-02
CVE-2023-47858 [MEDIUM] CWE-284 CVE-2023-47858: Mattermost fails to properly verify the permissions needed for viewing archived public channels, al
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams//channels/deleted endpoint.
nvd
CVE-2023-3582P4MEDIUMCVSS 4.3≥ 7.8.0, < 7.8.7≥ 7.9.0, < 7.9.5+1 more2023-07-17
CVE-2023-3582 [MEDIUM] CWE-863 CVE-2023-3582: Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privi
Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privileged authenticated user to link a Board to a private channel they don't have access to,
nvd
CVE-2024-10241P4MEDIUMCVSS 4.3≥ 9.5.0, < 9.5.102024-10-29
CVE-2024-10241 [MEDIUM] CWE-284 CVE-2024-10241: Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is en
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
nvd
CVE-2024-5272P4MEDIUMCVSS 4.3≥ 8.1.0, < 8.1.13≥ 9.5.0, < 9.5.4+1 more2024-05-26
CVE-2024-5272 [MEDIUM] CWE-284 CVE-2024-5272: Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by finished.
nvd
CVE-2025-27933P4MEDIUMCVSS 4.3≥ 9.11.0, < 9.11.9≥ 10.3.0, < 10.3.4+1 more2025-03-21
CVE-2025-27933 [MEDIUM] CWE-863 CVE-2025-27933: Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce cha
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public
nvd
CVE-2024-12247P4MEDIUMCVSS 4.3≥ 9.7.0, < 9.7.6≥ 9.8.0, < 9.8.3+1 more2024-12-05
CVE-2024-12247 [MEDIUM] CWE-863 CVE-2024-12247: Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate per
Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.
nvd
CVE-2025-64641P4MEDIUMCVSS 4.1≥ 10.11.0, < 10.11.8≥ 10.12.0, < 10.12.4+2 more2025-12-24
CVE-2025-64641 [MEDIUM] CWE-863 CVE-2025-64641: Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted with affected posts
nvd
CVE-2018-21259P4MEDIUMCVSS 5.3fixed in 4.8.2≥ 4.9.0, < 4.9.4+1 more2020-06-19
CVE-2018-21259 [MEDIUM] CWE-20 CVE-2018-21259: An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to
An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.
nvd